Live data from Hacker News

T-mobile password reset does not allow you to type the letter "V"

support.t-mobile.com

1–10 of 85 posts

Re: T-mobile password reset does not allow you to type the letter "V"

#5
post #2

Wait till this guy figures out that T-Mobile also stores his password in plain text.

I wonder if it's a bad idea to disclaim that you store passwords in plain text (when you actually use PBKDF2 or something) to trick users into making more secure passwords.

Re: T-mobile password reset does not allow you to type the letter "V"

#6
Their entire site is a really bad example of ASP.NET development. As someone who knows the technology well, it can make great sites. It just rarely does.

I like my T Mobile service but there's something odd with their backend systems and/or customer service. I logged in to disable their "WebGuard" service that seemed to be blocking pages at random. It required address and social security verification, but I couldn't get it to verify my details.

I called, and the customer service agent hopefully told me that my address didn't exist. I live in the middle of New York, and I've never had this issue before. I can't help but wonder what crazy verification system they're using.

Re: T-mobile password reset does not allow you to type the letter "V"

#8
post #2

Wait till this guy figures out that T-Mobile also stores his password in plain text.

I wonder if it's a bad idea to disclaim that you store passwords in plain text (when you actually use PBKDF2 or something) to trick users into making more secure passwords.

Personally, that'd steer me away.

Re: T-mobile password reset does not allow you to type the letter "V"

#9
post #2

Wait till this guy figures out that T-Mobile also stores his password in plain text.

I wonder if it's a bad idea to disclaim that you store passwords in plain text (when you actually use PBKDF2 or something) to trick users into making more secure passwords.

It'd be terrible PR though

Re: T-mobile password reset does not allow you to type the letter "V"

#10
post #2

Wait till this guy figures out that T-Mobile also stores his password in plain text.

I wonder if it's a bad idea to disclaim that you store passwords in plain text (when you actually use PBKDF2 or something) to trick users into making more secure passwords.

The type of users that use insecure passwords probably don't care about or understand the implications of plain text passwords.
Post reply on HN